<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1074" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-08-05T10:17:19+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1074</id>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2013-08-05T10:17:19+01:00</updated>
<published>2013-08-05T10:17:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4204#p4204</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4204#p4204"/>
<title type="html"><![CDATA[Re: [SOLVED] OpenPGP app no longer accepts PIN after unblock]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4204#p4204"><![CDATA[
<div class="quotetitle">kylef wrote:</div><div class="quotecontent"><br />can you confirm you've changed the file since posting your sha1sum? i don't want to brick my neo.<br /></div><br /><br />I've just tried to upload the new version having SHA1 hash 8a2e02bf21b05751216ddb6380833329a75500f2 and I can confirm it works.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Mon Aug 05, 2013 10:17 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2013-08-04T21:45:51+01:00</updated>
<published>2013-08-04T21:45:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4200#p4200</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4200#p4200"/>
<title type="html"><![CDATA[Re: [SOLVED] OpenPGP app no longer accepts PIN after unblock]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4200#p4200"><![CDATA[
<div class="quotetitle">kylef wrote:</div><div class="quotecontent"><br />every time i download i get a different sha1sum<br />8a2e02bf21b05751216ddb6380833329a75500f2  openpgpcard.cap<br /><br />can you confirm you've changed the file since posting your sha1sum? i don't want to brick my neo.<br /></div><br /><br />Yes, they have uploaded a new version as of July 4th, I get identical SHA1 hash. I couldn't test it yet, but using gpshell to upload new app version should only affect the OpenPGPcard application and nothing else (thus nearly zero chance of bricking the Yubikey Neo token). Nevertheless, it would be a good idea for Yubico to use SSL/TLS for downloads as well as forums. We are playing security game here, right? <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Sun Aug 04, 2013 9:45 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[kylef]]></name></author>
<updated>2013-08-02T21:09:42+01:00</updated>
<published>2013-08-02T21:09:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4196#p4196</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4196#p4196"/>
<title type="html"><![CDATA[Re: [SOLVED] OpenPGP app no longer accepts PIN after unblock]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4196#p4196"><![CDATA[
klas-<br />every time i download i get a different sha1sum<br />8a2e02bf21b05751216ddb6380833329a75500f2  openpgpcard.cap<br /><br />can you confirm you've changed the file since posting your sha1sum? i don't want to brick my neo.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2523">kylef</a> — Fri Aug 02, 2013 9:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2013-06-04T15:05:34+01:00</updated>
<published>2013-06-04T15:05:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4019#p4019</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4019#p4019"/>
<title type="html"><![CDATA[Re: [QUESTION] OpenPGP app no longer accepts PIN after unblo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4019#p4019"><![CDATA[
Thanks, that worked.<br /><br />I used gpshell to upload new version of openpgpcard.cap (via RFID reader). The unblocking now works as expected.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Tue Jun 04, 2013 3:05 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Klas]]></name></author>
<updated>2013-06-03T12:52:01+01:00</updated>
<published>2013-06-03T12:52:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4018#p4018</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4018#p4018"/>
<title type="html"><![CDATA[Re: [QUESTION] OpenPGP app no longer accepts PIN after unblo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4018#p4018"><![CDATA[
Hello,<br /><br />Yes, there was a bug in unblock with admin pin in the openpgp applet (<!-- m --><a class="postlink" href="https://github.com/Yubico/ykneo-openpgp/commit/ae946ad142efa730e2372b00572e9a473319de12">https://github.com/Yubico/ykneo-openpgp ... 473319de12</a><!-- m -->). It is fixed in the source repo and new Neos sent out have the fix.<br /><br />If you are interested in reloading the openpgp applet yourself there are instructions for building and loading it at <!-- m --><a class="postlink" href="https://github.com/Yubico/ykneo-openpgp">https://github.com/Yubico/ykneo-openpgp</a><!-- m --> (alternatively you can download it pre-built from <!-- m --><a class="postlink" href="http://static.yubico.com/var/uploads/files/openpgpcard.cap">http://static.yubico.com/var/uploads/fi ... gpcard.cap</a><!-- m --> sha1sum: 06290c8f52ea4711157d26400aaf3670816bd147). Please note that reloading the applet will clear it of all generated keys.<br /><br />/klas<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2019">Klas</a> — Mon Jun 03, 2013 12:52 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2013-06-04T16:17:35+01:00</updated>
<published>2013-05-28T14:33:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4011#p4011</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4011#p4011"/>
<title type="html"><![CDATA[[SOLVED] OpenPGP app no longer accepts PIN after unblock]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1074&amp;p=4011#p4011"><![CDATA[
Hi,<br /><br />the OpenPGP applet on Yubikey Neo no longer accepts the user PIN and the PIN try counter won't decrease from 3 even if I enter wrong PIN. It happened after unblocking the PIN once via &quot;gpg --change-pin&quot;, any operation requiring user PIN like signing no longer works.<br /><br />From &quot;gpg --card-status&quot; (gnupg 2.0.19 on Scientific Linux 6.4) :<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Application ID ...: D2760001240102000000000000010000<br />Version ..........: 2.0<br />Manufacturer .....: test card<br />Serial number ....: 00000001<br />Name of cardholder: NFCTest Yubikey<br />Language prefs ...: en<br />Sex ..............: unspecified<br />URL of public key : &#91;not set&#93;<br />Login data .......: &#91;not set&#93;<br />Signature PIN ....: forced<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 6<br />Signature key ....: EBE7 BBA6 0F98 FEC5 38A7  9AE5 D24B 3700 FE6A 4090<br />      created ....: 2013-05-23 09:07:45<br />Encryption key....: 912C A861 FCBC CC33 4A3C  84F4 9F28 C5C9 C031 CCB5<br />      created ....: 2013-05-23 09:07:45<br />Authentication key: 5874 40A4 D735 F0D4 FD88  492C 2A16 94A5 3DC1 DDD4<br />      created ....: 2013-05-23 09:07:45<br />General key info..: pub  2048R/FE6A4090 2013-05-23 Neokey &lt;yubi@nowhere.cz&gt;<br />sec&gt;  2048R/FE6A4090  created: 2013-05-23  expires: 2015-05-23<br />                      card-no: 0000 00000001<br />ssb&gt;  2048R/3DC1DDD4  created: 2013-05-23  expires: 2015-05-23<br />                      card-no: 0000 00000001<br />ssb&gt;  2048R/C031CCB5  created: 2013-05-23  expires: 2015-05-23<br />                      card-no: 0000 00000001<br /></div><br /><br />Strangely enough, admin PIN still works (also admin PIN try counter works), e.g. I can change name using admin commands. However user PIN still doesn't work even if changed/unblocked via 'gpg --change-pin', see below. <br /><br />The result is the same whether using NFC or connecting via USB CCID. Sniffing and checking out some authenthication APDUs, I pasted them from pcscd log:<br /><br />Authentication with user PIN (PW1) always fails:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">APDU: 00 A4 04 00 06 D2 76 00 01 24 01  #select OpenPGP app - ok<br />SW: 90 00 <br /><br />APDU: 00 20 00 81 06 31 32 33 34 35 36 # user PIN fail, now always says there's 3 tries left, even if wrong PIN is supplied<br />SW: 63 C3 <br /></div><br /><br />But admin PIN seems OK, it looks it will even let us change user PIN:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">APDU: 00 A4 04 00 06 D2 76 00 01 24 01  #select OpenPGP app - ok<br />SW: 90 00 <br /><br />APDU: 00 20 00 83 08 31 32 33 34 35 36 37 38  #authenthicate with admin PIN 12345678 - ok<br />SW: 90 00 <br /><br />APDU: 00 2C 02 81 06 31 32 33 34 35 36 # change/reset PIN (PW1) to 123456 - seems ok <br />SW: 90 00 <br /></div><br /><br />But even after &quot;changing PIN&quot; the auth with the user PIN still fails in the same way - returns SW 63 C3.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Tue May 28, 2013 2:33 pm</p><hr />
]]></content>
</entry>
</feed>